Enable job alerts via email!

Engineer Pentesting

TN United Kingdom

Southampton

On-site

GBP 50,000 - 90,000

Full time

Today
Be an early applicant

Boost your interview chances

Create a job specific, tailored resume for higher success rate.

Job summary

Join a dynamic global organization as an Application and Product Security Engineer, where you will conduct penetration testing and security evaluations across a wide range of products—from embedded devices to cloud services. This role offers the opportunity to identify vulnerabilities, enhance security measures, and contribute to the development lifecycle of critical infrastructure solutions. You will collaborate with engineering teams, document findings, and help shape the security posture of innovative applications. If you are passionate about security and thrive in a fast-paced environment, this is the perfect opportunity for you.

Qualifications

  • 5+ years of experience in information, application, or embedded product security.
  • 2+ years of pentesting experience with a personal interest in CTFs.
  • Solid understanding of security protocols, cryptography, and IT risks.

Responsibilities

  • Conduct security evaluations and threat assessments of embedded systems.
  • Perform data bus monitoring and communications protocol analysis.
  • Create detailed technical reports and proof of concept code.

Skills

Penetration Testing
Security Evaluations
Threat Assessments
Reverse Engineering
Cryptography
Communication Skills

Education

Bachelor's Degree in Information Technology
Advanced Security Certifications (OSCP, CEH)

Tools

IDA Pro
WinDbg
BinWalk
Gitlab

Job description

Social network you want to login/join with:

Vertiv, a global organization with nearly 24,000 employees, designs, builds, and services critical infrastructure that enables vital applications for data centers, communication networks, and commercial and industrial facilities. We support today’s growing mobile and cloud computing markets with a portfolio of power, thermal, and infrastructure management solutions.

The Application and Product Security Engineer (Penetration Testing) is responsible for conducting security pen testing, monitoring, and auditing within a dynamic global organization. The products under test will range from embedded devices to cloud services, with some tests being white box and others black box engagements.

A successful engineer will evaluate the product to identify weaknesses in design and implementation, focusing on those vulnerabilities to find security gaps under the guidance of senior engineers and testing leads. The engineer should clearly document findings, analysis, and prepare detailed reports.

What Would Be the Perfect Qualifications?

In addition to performing internal application and product security assessments, the Penetration Tester will support the following duties:

  • Conduct security evaluations and threat assessments of embedded systems, mobile applications, and web applications.
  • Research to find new vulnerabilities and enhance existing capabilities.
  • Circumvent security protection methods and techniques.
  • Perform data bus monitoring (snooping) and data injection.
  • Conduct communications protocol analysis in embedded products and applications.
  • Conduct wireless communications channel snooping and data injection.
  • Learn to reverse engineer complex systems and protocols.
  • Create detailed technical reports and proof of concept code to document findings.
  • Perform system breakdown of the project/product before testing, identify testing requirements, and plan activities with the help of senior/test engineers.
  • Provide proactive interaction with engineering teams regarding testing needs, progress, and detailed analysis reports.
What kind of work will you be doing?
  • Bachelor’s Degree in Information Technology, Computer Science, or related field is highly desirable.
  • Advanced security certifications such as OSCP, CEH, or equivalent.
  • 5+ years of experience in information, application, or embedded product security and/or IT risk management.
  • 2+ years of pentesting experience with personal interest or experience in CTFs, HacktheBox, etc.
  • Solid understanding of security protocols, cryptography, authentication, and authorization.
  • Good knowledge of current IT risks and security solutions.
  • Ability to communicate effectively with various personnel to articulate and enforce security measures.
  • Excellent written and verbal communication skills and business acumen.
  • Strong ability to establish partnerships, influence change, and achieve results in a dynamic environment.
  • Meaningful technical contributions to the development lifecycle of applications, products, or services.
How Does Your Ideal Experience Look?
  • Experience in embedded systems/software and web applications development.
  • Familiarity with compilers, debuggers, disassemblers, and analysis tools.
  • Experience with binary analysis tools such as IDA Pro, WinDbg, BinWalk, etc.
  • Understanding of cryptographic algorithms, protocols, and their vulnerabilities.
  • Knowledge of network protocols and packet-level development.
  • Experience with microcontroller programming and debugging interfaces.
  • Exposure to Layer 2, Layer 3 networking, and QoS.
  • Knowledge of malware/botnet exploits targeting embedded systems.
  • Experience with operating systems like Windows, Linux, Android, and iOS.
  • Understanding of the computer boot process and boot loaders.
  • Additional practical skills such as static memory analysis, data element extraction, etc., are a plus.
  • Experience with Gitlab for issue management is preferred.
Get your free, confidential resume review.
or drag and drop a PDF, DOC, DOCX, ODT, or PAGES file up to 5MB.

Similar jobs

SRE - Freelance Security & Automation Engineer (Pentesting Focus)

Mindrift

London

Remote

GBP 30,000 - 60,000

30+ days ago

SRE - Freelance Security & Automation Engineer (Pentesting Focus)

Mindrift

Birmingham

Remote

GBP 30,000 - 60,000

30+ days ago

SRE - Freelance Security & Automation Engineer (Pentesting Focus)

Mindrift

Leeds

Remote

GBP 30,000 - 60,000

30+ days ago

SRE - Freelance Security & Automation Engineer (Pentesting Focus)

Mindrift

Manchester

Remote

GBP 30,000 - 60,000

30+ days ago